Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 CVE-2026-28573

CVE-2026-28573_CVE-2026-28573

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of serv...

Google Android 14 CVE
MEDIUM 6.1 CVE-2026-12137

SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameter_CVE-2026-12137

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cr...

phppoet SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager CVE
MEDIUM 6.4 CVE-2026-12136

SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-12136

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcod...

phppoet SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager CVE
MEDIUM 4.3 CVE-2026-12111

Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter_CVE-2026-12111

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. Thi...

codepeople Appointment Booking Calendar CVE
LOW 2.7 CVE-2026-12102

UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter_CVE-2026-12102

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecur...

stiofansisland UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP CVE
MEDIUM 6.4 CVE-2026-12098

PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field_CVE-2026-12098

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all...

blubrry PowerPress Podcasting plugin by Blubrry CVE
HIGH 7.2 CVE-2026-11395

CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host_CVE-2026-11395

The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_t...

mariovalney CF7 to Webhook CVE
HIGH 7.1 CVE-2026-8811

Path traversal in PDF generation module_CVE-2026-8811

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to cr...

SEPPmail AG Secure Email Gateway CVE
MEDIUM 6.4 CVE-2026-8039

Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting_CVE-2026-8039

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' ...

dijitul Fancy Testimonials CVE
MEDIUM 5.1 CVE-2026-50643

Out‑of‑Bounds Read in 8cc_CVE-2026-50643

8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controll...

rui314 8cc b480958 CVE